Amadey

S1025

Malware.View on attack.mitre.org

About this malware

Amadey is a Trojan bot that has been used since at least October 2018.

Techniques used17

Procedure examples17

TechniqueProcedure example
T1005
Data from Local System

Amadey can collect information from a compromised host.

T1016
System Network Configuration Discovery

Amadey can identify the IP address of a victim machine.

T1027
Obfuscated Files or Information

Amadey has obfuscated strings such as antivirus vendor names, domains, files, and others.

T1033
System Owner/User Discovery

Amadey has collected the user name from a compromised host using `GetUserNameA`.

T1041
Exfiltration Over C2 Channel

Amadey has sent victim data to its C2 servers.

T1071.001
Web Protocols

Amadey has used HTTP for C2 communications.

T1082
System Information Discovery

Amadey has collected the computer name and OS version from a compromised machine.

T1083
File and Directory Discovery

Amadey has searched for folders associated with antivirus software.

T1105
Ingress Tool Transfer

Amadey can download and execute files to further infect a host machine with additional malware.

T1106
Native API

Amadey has used a variety of Windows API calls, including `GetComputerNameA`, `GetUserNameA`, and `CreateProcessA`.

T1112
Modify Registry

Amadey has overwritten registry keys for persistence.

T1140
Deobfuscate/Decode Files or Information

Amadey has decoded antivirus name strings.

T1518.001
Security Software Discovery

Amadey has checked for a variety of antivirus products.

T1547.001
Registry Run Keys / Startup Folder

Amadey has changed the Startup folder to the one containing its executable by overwriting the registry keys.

T1553.005
Mark-of-the-Web Bypass

Amadey has modified the `:Zone.Identifier` in the ADS area to zero.

View all 17 procedure examples

Groups that use it2

Campaigns0

None recorded.

References2

  1. BlackBerry Amadey 2020 Open source
    Kasuya, M. (2020, January 8). Threat Spotlight: Amadey Bot Targets Non-Russian Users. Retrieved July 14, 2022.
  2. Korean FSI TA505 2020 Open source
    Financial Security Institute. (2020, February 28). Profiling of TA505 Threat Group That Continues to Attack the Financial Sector. Retrieved July 14, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.